Описание
Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated users via the Shutdown message.
Ссылки
- Vendor Advisory
- US Government Resource
- Vendor Advisory
- US Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 4.3.6 (включая)
cpe:2.3:a:liferay:liferay_enterprise_portal:*:*:*:*:*:*:*:*
EPSS
Процентиль: 52%
0.00285
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-352
Связанные уязвимости
debian
почти 18 лет назад
Cross-site request forgery (CSRF) vulnerability in the Admin portlet i ...
github
больше 3 лет назад
Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated users via the Shutdown message.
EPSS
Процентиль: 52%
0.00285
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-352